← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Don't Get Caught in the Headlights - DeerStealer Analysis
In May 2025, threat actors increasingly attempted to download and execute a sophisticated malware known as HijackLoader, often using DeerStealer—an information-stealer marketed on dark-web forums by the user "LuciferXfiles"—as the final payload. The primary access method observed in these attack chains is called ClickFix, which exploits users by redirecting them to phishing pages prompting the execution of malicious commands in the Windows Run Prompt. The initial sequence involves loading an unsigned version of a legitimate DLL named "cmdres.dll," which has been manipulated to facilitate the execution of HijackLoader.
MITRE ATT&CK & Malware Families
Indicators of Compromise (9 / 52 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 02d0f858069426ee5bbf04d5d85ff053d8f86867f4fbedb5ef70f78cb2acf086 | — | 2025-06-13 | |
| FileHash-SHA256 | 163cfcb8a2c2e14cb77e0d735b87f56ae653d58ad5c69c536396f2936afd1c72 | — | 2025-06-13 | |
| FileHash-SHA256 | 24475ae7781189075f64a2de1a7d1fd69b341b7adee67f0bd2286cfbf1f0b7f9 | — | 2025-06-13 | |
| FileHash-SHA256 | 3a03afc1313854359603522e0792f6a8f9153519eac645cf5811824d936cfbc7 | — | 2025-06-13 | |
| FileHash-SHA256 | 4eae5c64da09969299fd3c1fe05d91f67a425a1e1431b926fda289e4b94fd550 | — | 2025-06-13 | |
| FileHash-SHA256 | 674476acafaa975bb80ee9ea7ae24e0bbedb1d1d5c3b3871f718b857b066579d | — | 2025-06-13 | |
| FileHash-SHA256 | 9163f9237ad869a74715f9b126f7c577bd1f12afb8eae37ba07c11f00a39fa3e | — | 2025-06-13 | |
| FileHash-SHA256 | e34d753f2b992cf74c1b9db61bad4d6c6089ab8ef9fb942c865290b2dd64b4ad | — | 2025-06-13 | |
| FileHash-SHA256 | eb17f8296482b0c096a2249844a62988b6abdd8ffe8cbbe3398f422968d46875 | — | 2025-06-13 |